CommentaryMarkdown PR reviewLegal
Docs
Legal

Security

Effective March 18, 2026Last updated March 18, 2026

This page is a plain-language summary of Commentary’s current security posture. It is not a promise of formal certification, audit status, or a guarantee that incidents will never occur.

Access and authentication

Commentary uses GitHub App user authorization as the default sign-in path and supports personal access tokens where workflow requirements make that necessary.

Authenticated actions, such as commenting, replies, and private repository access, depend on the GitHub identity and repository access available to the connected user. Interactive review actions continue to run as that connected GitHub user.

Data protection and operational controls

Commentary uses Azure-backed infrastructure to host and operate the service. Tokens are intended to remain encrypted at rest, and app-native review state is separated from raw provider content where practical.

Commentary also maintains rate-limit handling, request telemetry, and operational monitoring intended to detect service failures and abnormal behavior quickly.

Current limitations

Commentary is an early-stage developer tool. Some controls are still evolving, and certain legal, billing, and operational processes remain founder-reviewable placeholders rather than final enterprise commitments.

Users should avoid storing secrets or unrelated regulated data in review comments unless the repository workflow itself is already approved for that content.

Reporting security concerns

To report a security concern, contact support@commentary.dev and include enough detail for reproduction, impact assessment, and a secure response process.

On this page
Access and authenticationData protection and operational controlsCurrent limitationsReporting security concerns
CommentaryMarkdown review built around rendered documents, app-native comments, and GitHub trust cues.
PrivacyTermsCookiesCopyright / DMCAContactSecurityDocs